GitHub Copilot App Adds Local Sandboxing, Off by Default, to Contain Unintended Agent Commands
GitHub added an opt-in, OS-level sandbox to the Copilot desktop app that limits agent file, network, and credential access, failing closed if unsupported.
Signal
52 articles covering "security"
GitHub added an opt-in, OS-level sandbox to the Copilot desktop app that limits agent file, network, and credential access, failing closed if unsupported.
Homebrew 7.0.0 adds a brew vulns scanner and advisory database, swaps Linux Bubblewrap sandboxing for Landlock, and patches a cask sandbox-escape flaw.
Manifold Security found eight flaws across seven AI coding agents that let a repository's git config silently execute code the moment it is opened.
CVE-2026-80590, a bug letting unprivileged users trigger a kernel panic via mismarked IPv4/IPv6 fragments, is fixed across eight stable and longterm kernel releases.
PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 landed August 13 alongside 19 Beta 3, patching 28 security flaws and over 110 bugs, with PostgreSQL 14 set to lose support in November.
Cloudflare opens a private beta of WriteGuard, a policy and audit layer that classifies and can block risky write actions AI agents take through MCP servers.
rsync 3.5.0, released August 13, patches 33 CVEs found through an audit, fuzzing, and outside researchers, following the disruptive May 3.4.3 security release.
OpenAI released the command-line tool and SDK for Codex Security, formerly Aardvark, under Apache-2.0, while the underlying scanner stays limited-beta.
Microsoft's bounty program paid over $20 million to 562 researchers this year after expanding scope to cover open-source software and third-party components.
Go 1.27's second release candidate fixes an os.Root symlink escape and a crypto/tls Encrypted Client Hello privacy leak, alongside the language's first generic methods.
Node.js shipped 11 CVE fixes across three High-severity HTTP/2 and Permission Model bugs on July 29, after two delays, while EOL versions 18 and 20 get nothing upstream.
Kyverno 1.18 patches two flaws in its HTTP-based policy execution, blocks loopback and metadata addresses by default, and flags ClusterPolicy for deprecation later this year.